PluginProbe
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO / 2.11.0
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO v2.11.0
2.11.0 2.10.0 2.9.0 2.8.0 2.7.0 2.6.0 2.5.0 2.4.0 2.3.0 2.2.0 2.1.1 2.1.0 2.0.2 2.0.1 2.0.0 1.32.0 1.31.0 1.30.0 1.29.0 1.28.0 1.27.0 1.26.0 1.25.0 trunk 1.0.0 All 52 releases
← All changes | includes/abilities/content/class-update-post-seo.php +39 -1 2.9.0 → 2.11.0 View file →
@@ -68,8 +68,16 @@
68 68 ],
69 69 'robots_meta_enabled' => [ 'type' => 'boolean' ],
70 70 'robots_meta' => [ 'type' => 'object' ],
71 71 'advanced_robots_meta' => [ 'type' => 'object' ],
72 + 'exclude_from_search' => [
73 + 'type' => 'boolean',
74 + 'description' => __( 'Keep this post out of this site\'s own search results. Not noindex: search engines are unaffected, and the post keeps its own URL. Use robots_meta for search engines.', 'thinkrank' ),
75 + ],
76 + 'exclude_from_archives' => [
77 + 'type' => 'boolean',
78 + 'description' => __( 'Keep this post out of category, tag, author, date and blog listings on this site. Not noindex: search engines are unaffected, and the post keeps its own URL, its feed entry and its sitemap entry.', 'thinkrank' ),
79 + ],
72 80 'og_title' => [ 'type' => 'string' ],
73 81 'og_description' => [ 'type' => 'string' ],
74 82 'og_image' => [ 'type' => 'string' ],
75 83 'twitter_title' => [ 'type' => 'string' ],
@@ -208,9 +216,11 @@
208 216
209 217 $has_robots = array_key_exists( 'robots_meta', $settings ) || array_key_exists( 'advanced_robots_meta', $settings );
210 218
211 219 if ( array_key_exists( 'robots_meta_enabled', $settings ) ) {
212 - $fields['thinkrank_robots_meta_enabled'] = (int) (bool) $settings['robots_meta_enabled'];
220 + // Sanitized for the same reason as the visibility flags below: the
221 + // string "false" passes the schema and is truthy in PHP.
222 + $fields['thinkrank_robots_meta_enabled'] = (int) rest_sanitize_boolean( $settings['robots_meta_enabled'] );
213 223 } elseif ( $has_robots ) {
214 224 // The metabox only persists robots blobs when the toggle key is
215 225 // present; default to the currently stored value (or 1).
216 226 $existing = get_post_meta( $post_id, '_thinkrank_robots_meta_enabled', true );
@@ -222,8 +232,36 @@
222 232 }
223 233
224 234 if ( array_key_exists( 'advanced_robots_meta', $settings ) ) {
225 235 $fields['thinkrank_advanced_robots_meta'] = (string) wp_json_encode( (array) $settings['advanced_robots_meta'] );
236 + }
237 +
238 + // On-site visibility (#633). get-post-seo already reports both, because
239 + // it returns get_post_metadata() wholesale — so without these an agent
240 + // could read a field it had no way to change, which is the worst shape
241 + // a tool pair can have.
242 + //
243 + // The value goes through Metabox_Manager::save_visibility_meta(), which
244 + // stores 1 on a truthy submission and DELETES the meta on a falsy one,
245 + // so '' is how a flag is cleared. Passing the boolean straight through
246 + // would work too; the string keeps this in the same shape as every
247 + // other field in this map.
248 + //
249 + // rest_sanitize_boolean() rather than PHP truthiness: WP_Ability only
250 + // VALIDATES the input against the schema, it never sanitizes it, and
251 + // rest_is_boolean() accepts the strings 'true'/'false'/'1'/'0' for a
252 + // boolean property. So a caller that sends "false" — which the schema
253 + // accepts — reaches this line with a truthy string and would have the
254 + // flag SET, the opposite of what it asked for, reported as a success.
255 + foreach (
256 + [
257 + 'exclude_from_search' => 'thinkrank_exclude_from_search',
258 + 'exclude_from_archives' => 'thinkrank_exclude_from_archives',
259 + ] as $key => $field
260 + ) {
261 + if ( array_key_exists( $key, $settings ) ) {
262 + $fields[ $field ] = rest_sanitize_boolean( $settings[ $key ] ) ? '1' : '';
263 + }
226 264 }
227 265
228 266 return $fields;
229 267 }